3913 token Hack
What happened
Deflationary token 3913 suffers a $31,354 USD loss in a flash loan attack on BNB Smart Chain.
On November 2, 2023, the deflationary token 3913 on BNB Smart Chain was exploited through a flash loan attack. The attacker utilized a loophole in the token's in_transfer function, which was designed to give bonuses to new token holders when a Pancake pair sends tokens to the new user. However, the contract failed to account for a malicious user forcing a Pancake/Uniswap pair to transfer tokens to any address via a skim() call.
The attacker took a flash loan, bought 3913 tokens, and repeatedly transferred these tokens to the pair address while calling skim(), tricking the contract into giving away all available bonuses. As of November 20, 2023, the stolen funds, amounting to $31,354.82 USD, still remain in the scammer's address as BSC-USD.
Attacker address:
https://bscscan.com/address/0xb29F18B8…8D8ae7
Malicious transaction:
https://bscscan.com/tx/0x8163738d…6199ed
Malicious contract:
https://bscscan.com/address/0x783FBEa4…025E83
Case & protocol details
Evidence & learning
Attack pattern
Compare incidents →Sources and on-chain records
- report Report twitter.com
Practice this exploit pattern safely
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.